Sign In | Sign Up

My Profile

kuki
191891
.....
Points: 679
Country: India
Gender: Male
Constellation: Gemini

Shortcuts

Categories

Post

Gmail Security Flaw Exposed, Very important for Gmail users
Size: Large, Medium, Small Fri Feb 29, 08 06:49 AM | Category: All
2
after a lot of investigation I have finally found out the root cause of the ordeal I had to go through.

The reason behind the theft of my account and password is not because some one stole my password but because of a vulnerability in Google'e email system, Gmail.

I will not go into the technical details however for those who use gmail, I would recommend the following

1. Check the filters in your mail settings and make sure that all the filters in your gmail are the ones you created.

2. Install a piece of software called NoScript. It is available from this link http://noscript.net/

For those who use other browsers, they will have to find an anti-Cross-site request forgery, or simply put anti-CSRF software which prevents cross site scripting attacks.

This vulnerability is a very serious one and it is a big shame that a company as big as Google has not informed its users of the security flaw for the past coulple of months.

If you are a victim of such an attack, you will never even know and the attacker will receive all your email communications. I am still unable to figure out how the attacker got access to my PayPal account. However, I am slowly catching up.

For a more detailed overview , you can read the following articles

http://www.gnucitizen.org/blog/google-gmail-e-mail-hijack-technique/

Thanks to the original poster who showed me the light.

http://www.davidairey.com/google-gmail-security-hijack/
N/A
Link: http://blog.bitcomet.com/post/18270/ ©
Add to favorites | QuoteReport Reads (423) | Comments (1)

CommentsReload

Ichisanno (Michi) Fri Feb 29, 08 09:42 AM

mm..

thanks for the info.

Wish I Had An Angel

TOP